Official agent skill

Auth Store Debug

by vercel-labs in vercel-labs/vercel-openclaw-archived

Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCALREADONLY, Redis vs memory store, keyspace namespacing, and metadata shape migrations.

OfficialMITAuto-check passedDatabases

Install Auth Store Debug

skills CLI
$ npx skills add vercel-labs/vercel-openclaw-archived --skill auth-store-debug -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vercel-labs/vercel-openclaw-archived auth-store-debug --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vercel-labs/vercel-openclaw-archived.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/auth-store-debug .claude/skills/auth-store-debug && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auth-store-debug
GitHub stars
117
Token cost
~465 tokens
SKILL.md length
159 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
MIT

At a glance

Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCALREADONLY, Redis vs memory store, keyspace namespacing, and metadata shape migrations.

  • Route authorization
  • SKILL.md covers Evidence First, Critical Splits, Fix Boundaries and Verification
  • Calls pnpm and node
  • Redis persistence

What it does

Auth Store Debug is an agent skill from vercel-labs/vercel-openclaw-archived, published by the product's own GitHub organization. Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCALREADONLY, Redis vs memory store, keyspace namespacing, and metadata shape migrations. Use when login, route authorization, Redis persistence, or metadata state is suspect.

Its SKILL.md is about 470 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering Web application vulnerabilities, Debugging and Authorization and RBAC. It works with Vercel and Redis. The repository describes itself as: Deploy OpenClaw on Vercel. The licence is MIT.

When your agent uses it

  • Route authorization
  • Redis persistence
  • Metadata state is suspect

Example prompts

  • “/auth-store-debug”

What it can do on your machine

Read from SKILL.md and the folder at commit d592f7b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auth Store Debug loads about 465 tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 159 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~465

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vercel-labs/vercel-openclaw-archived at commit d592f7b, republished under its MIT licence (© vercel-labs). 159 words, ~465 tokens.

Download SKILL.mdSave it as .claude/skills/auth-store-debug/SKILL.md (or your agent's skills folder).
name
auth-store-debug
description
Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCAL_READ_ONLY, Redis vs memory store, keyspace namespacing, and metadata shape migrations. Use when login, route authorization, Redis persistence, or metadata state is suspect.

Auth Store Debug

Use this skill when request authorization, session behavior, store persistence, or metadata shape is the likely problem.

Evidence First

Collect:

  • Auth mode and Vercel/local environment from admin/preflight surfaces.
  • Request method, route, status, and whether bearer or cookie auth was used.
  • GET /api/admin/logs filtered for auth., store., session., preflight..
  • Store backend reported by deployment contract.
  • Sanitized metadata shape when needed. Never print secrets, session keys, Redis URLs, or cookies.

Critical Splits

  • Deployment Protection auth vs app auth.
  • Bearer admin-secret auth vs encrypted session cookie auth.
  • CSRF applies to cookie-based mutations, not bearer mutations.
  • LOCAL_READ_ONLY=1 intentionally blocks admin mutations locally.
  • Redis connects only on deployed Vercel runtimes; local/CI use memory store even if Redis envs exist.
  • OPENCLAW_INSTANCE_ID changes namespace and does not migrate old state.

Fix Boundaries

  • Auth: src/server/auth/{admin-auth,admin-secret,session,vercel-auth,route-auth}.ts.
  • Store: src/server/store/{store,redis-store,memory-store,keyspace}.ts, src/shared/types.ts.
  • Routes: only the affected route handler.
  • Docs/env contract: .env.example, README.md, CONTRIBUTING.md, CLAUDE.md.

Verification

bash
node scripts/verify.mjs --steps=test,typecheck
pnpm check:verify-contract
lat check

Run pnpm check:verify-contract when env vars, auth mode docs, or operator instructions change.

© vercel-labs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/auth-store-debug of vercel-labs/vercel-openclaw-archived.

Open the folder on GitHubat commit d592f7b

Compare with similar skills

Auth Store Debug next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auth Store Debug compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auth Store Debug this skillvercel-labs/vercel-openclaw-archived117—~465Automated safety check: PassMIT
SQL Code Reviewtotvs/engpro-advpl-tlpp-skills141—~3.5kAutomated safety check: PassMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
SQL Code Reviewgithub/awesome-copilot40k1 repos~2.2kAutomated safety check: PassMIT
Frontmcp Setupagentfront/frontmcp146—~5.8kAutomated safety check: PassApache-2.0
Azure Cache RedisMicrosoftDocs/Agent-Skills775—~2.9kAutomated safety check: PassCC-BY-4.0

Similar skills

  • SQL Code Review

    totvs/engpro-advpl-tlpp-skills

    Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle).

    141 GitHub stars~3.5k tokensUpdated 2 days ago
    DatabasesAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • SQL Code Review

    github/awesome-copilot

    Official

    Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server, Oracle).

    40k GitHub starsUsed in 1 repo~2.2k tokens
    DatabasesAuto-check passed
  • Frontmcp Setup

    agentfront/frontmcp

    A skill your agent uses when starting, scaffolding, or organizing a FrontMCP project.

    146 GitHub stars~5.8k tokensUpdated today
    DatabasesAuto-check passed
  • Azure Cache Redis

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Cache for Redis development including troubleshooting, best practices, decision making, architecture & design patterns, security, configuration, and deployment.

    775 GitHub stars~2.9k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Redis Security

    redis/agent-skills

    Official

    Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules…

    165 GitHub starsUsed in 1 repo~918 tokens
    DatabasesAuto-check passed

More from vercel-labs/vercel-openclaw-archived

All 16 skills in this repo
  • Channel Debug Core

    vercel-labs/vercel-openclaw-archived

    Official

    Channel webhook triage for vercel-openclaw Slack/Telegram/Discord/WhatsApp issues: prove deployment state, collect admin readiness endpoints, build evidence-first handoff before fixes.

    117 GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check: notes
  • Lat Md

    vercel-labs/vercel-openclaw-archived

    Official

    Writing and maintaining lat.md documentation files — structured markdown that describes a project's architecture, design decisions, and test specs.

    117 GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Cron Watchdog Debug

    vercel-labs/vercel-openclaw-archived

    Official

    Cron and watchdog debugging for vercel-openclaw: Vercel Cron auth, persisted OpenClaw jobs, cron wake keys, token refresh, restore oracle, hot spare, and watchdog reports.

    117 GitHub stars~1.6k tokensUpdated 4 mo ago
    Auto-check passed
  • Firewall AI Gateway Debug

    vercel-labs/vercel-openclaw-archived

    Official

    Firewall and Vercel AI Gateway debugging for vercel-openclaw: network policy allowlists, OIDC token refresh, AI Gateway transform rules, firewall learning/enforcement, and sandbox.update…

    117 GitHub stars~550 tokensUpdated 4 mo ago
    Auto-check passed
  • Gateway Proxy Debug

    vercel-labs/vercel-openclaw-archived

    Official

    Gateway and proxy debugging for vercel-openclaw: /gateway routing, HTML injection, WebSocket rewrite, gateway-token handoff, waiting page, status heartbeat, sandbox port URL cache, and proxy auth.

    117 GitHub stars~573 tokensUpdated 4 mo ago
    Auto-check passed
  • Openclaw Bootstrap Debug

    vercel-labs/vercel-openclaw-archived

    Official

    OpenClaw bootstrap, bundle, config, and restore-asset debugging for vercel-openclaw: openclaw.bundle sidecars, plugin discovery, channel catalog, restart scripts, config hashes, dynamic resume…

    117 GitHub stars~494 tokensUpdated 4 mo ago
    Auto-check passed

Works with

Questions about Auth Store Debug

What does Auth Store Debug do?

Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCALREADONLY, Redis vs memory store, keyspace namespacing, and metadata shape migrations. Auth Store Debug is an agent skill from vercel-labs/vercel-openclaw-archived, published by the product's own GitHub organization. Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCALREADONLY, Redis vs memory store, keyspace namespacing, and metadata shape migrations.

When should I use Auth Store Debug?

Auth Store Debug fits situations like: route authorization; redis persistence; metadata state is suspect.

How do I install Auth Store Debug in Claude Code?

Run `npx skills add vercel-labs/vercel-openclaw-archived --skill auth-store-debug -a claude-code`. Or copy the skill folder (.agents/skills/auth-store-debug in vercel-labs/vercel-openclaw-archived) into .claude/skills/auth-store-debug in your project. Claude Code loads it when a task matches its description.

How do I install Auth Store Debug in Codex?

Run `npx skills add vercel-labs/vercel-openclaw-archived --skill auth-store-debug -a codex`. Or copy the skill folder (.agents/skills/auth-store-debug in vercel-labs/vercel-openclaw-archived) into .agents/skills/auth-store-debug in your project. Codex loads it when a task matches its description.

Can I use Auth Store Debug in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel-labs/vercel-openclaw-archived --skill auth-store-debug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth-store-debug, .gemini/skills/auth-store-debug, .github/skills/auth-store-debug and .opencode/skills/auth-store-debug in your project.

What does Auth Store Debug need to run?

Going by SKILL.md and its folder, Auth Store Debug needs the command-line tools its instructions call (pnpm and node).

Does Auth Store Debug access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Auth Store Debug safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auth Store Debug use?

Auth Store Debug is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auth Store Debug use?

About 465 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auth Store Debug?

Skills that share tags, products or a category with Auth Store Debug: SQL Code Review (totvs/engpro-advpl-tlpp-skills, 141 stars), Security Review (github/awesome-copilot, 40k stars), SQL Code Review (github/awesome-copilot, 40k stars) and Frontmcp Setup (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auth Store Debug?

vercel-labs (a GitHub organization, an official publisher) maintains it in vercel-labs/vercel-openclaw-archived, which has 117 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on May 15, 2026.

Source: vercel-labs/vercel-openclaw-archived on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.